/ THE SHORT ANSWER
- 01Determine requirements from the relevant contract and information.
- 02Include security services and physical handling in the scope discussion.
- 03Budget for maintaining the boundary after implementation.
/ dotSuper point of view
An enclave is an operating boundary that people must sustain, not a shortcut created by buying a particular cloud product.
Begin with the information, not the product demo
A cloud proposal that covers only email may miss the steps where the information actually becomes usable.
The Defense Department's Level 2 scoping guide distinguishes CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets.[
1] Use those categories to structure a qualified scoping discussion.
Do not label everything outside the proposed cloud environment out of scope by default.
Select one representative job and trace it from request to archive.
Include rejected quotations and prototype work.
Sensitive information can remain in a sales inbox even when the corresponding production order was never created.
Resolve the contract question before the architecture question
Keep unresolved classification questions visible.
Treating every business document as CUI can create unnecessary work, while treating unmarked technical material as automatically unrestricted can create a different problem.
DFARS 252.204-7012 addresses safeguarding covered defense information and incident reporting, including conditions for external cloud services.[
2] Its obligations are separate details to evaluate alongside the required CMMC status.
A vendor's certification claim does not establish your contract compliance.
Record who can resolve uncertainty with the customer or contracting authority.
The IT provider should not be expected to infer contract intent from a folder name.
Architecture decisions become more defensible once the information categories and obligations are documented.
Use an asset map that follows the work
Then identify what protects those activities: identity systems, administrators, monitoring, backups, and support providers.
A security service can matter to the scope even when ordinary users never open it.
The decision table is a preparation tool for adviser review.
Each row should name an owner and describe observable behavior.
Screenshots of a configuration can support the map, but interviews with engineering and production often reveal the exceptions.
Include temporary arrangements such as remote troubleshooting, substitute workstations, and customer site visits.
An architecture that works only during a normal day may fail precisely when delivery pressure makes informal workarounds attractive.
| Workflow element | Question for the scope review |
|---|---|
| Customer portal | Where do downloaded files go? |
| Engineering | Which devices process controlled information? |
| Production | How are drawings displayed or printed? |
| External support | Who can access systems and evidence? |
| Security services | Which services protect the proposed scope? |
| Archives | Where do backups and old quotations remain? |
Worked hypothetical: the enclave that leaked into production
During a walkthrough, the team finds drawings downloaded to a shared programming computer and printed through an office server.
It also finds backups managed by an external IT provider.
Eight users is a staffing observation, not an assessment scope.
The team records those dependencies and asks its qualified adviser how each asset and service should be treated.
It does not assume that renaming the shared drive or moving email resolves the problem.
The resulting design may bring programming into the environment, change how production views drawings, or alter the backup arrangement.
Compare the disruption and continuing administration of each option.
This example offers no conclusion about the supplier's eventual level, assessment type, or certification.
Price the exceptions before committing
Ask how employees will quote a job, collaborate with an outside specialist, handle a network outage, and retrieve archived evidence.
Price the operational design as well as the licenses.
Require a responsibility matrix for patching, access reviews, incident handling, configuration changes, and evidence retention.
Distinguish what the provider supplies from what your organization must operate.
A responsibility described only as shared is difficult to manage during an incident.
Do not introduce an AI assistant merely because it is available in the selected suite.
Evaluate its data access, storage, external services, and outputs against the agreed boundary.
Useful summarization can still create new information paths that require review.
Maintain the boundary as jobs and systems change
Ask whether the change introduces a new information path or security dependency.
Record the decision before the convenience integration becomes normal practice.
Give production a usable exception route.
Employees need someone who can resolve access problems without encouraging personal email or removable-media shortcuts.
Track recurring exceptions because they may indicate that the approved design does not match the work.
The next concrete deliverable is a reviewed information-flow map and responsibility matrix.
Use those artifacts to compare providers on the same basis.
A purchase becomes more useful when everyone understands the operating boundary it is intended to support.
What this page cannot conclude
- 01This article does not determine a required CMMC level or certify an assessment boundary.
- 02The September 2024 DoD guide is interpretive guidance; current contract terms and applicable rules control.
- 03No assessment price, certification outcome, or universal implementation deadline is promised.
- 04This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01CMMC Scoping Guide Level 2, Version 2.13, September 2024US Department of Defense · accessed Sep 15, 2026
- 02DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident ReportingUS Department of Defense, Acquisition.gov · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Draw Your CMMC Boundary Before Buying the Platform. dotSuper. https://dotsuper.net/feeds/applied-systems/us-cmmc-enclave-scope-before-platform